cal.diy 6.2.0 Conferencing OAuth Callback Open Redirect via Unsigned State
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 5.3epss 0.2%
exploitation probability
0.2%top 90% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows attackers to redirect users to arbitrary URLs by crafting malicious state parameters. Attackers can exploit the unsigned state parameter and onErrorReturnTo field to silently redirect visitors from the trusted domain to attacker-controlled URLs for phishing attacks.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
calcom · cal.diypublic PoCs found — 1
cve_referencegithub.com/calcom/cal.diy/issues/29679unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.